In short: Lithune does not retain prompt or completion content and does not use it for model training. Limited technical metadata is processed to deliver, secure and account for the service.
1. Who is responsible
Levent Tuzun, a sole proprietor established in Türkiye and operating the Lithune brand, is the data controller for personal data whose processing purposes and means are determined by Lithune.
When the service is accessed through OpenRouter, OpenRouter also processes data under its own terms and privacy notice. OpenRouter's role is separate from Lithune's operation of the inference infrastructure.
2. Data we process
- Inference content: prompts, system messages, attachments and completions pass through Lithune systems and are processed transiently in memory by the model to generate a response. They are not retained by Lithune.
- Usage metadata: the API credential used, timestamp, request count, prompt-token count and completion-token count.
- Web access logs: Lithune has disabled Nginx access logging for both the public website and API. Normal requests are not written to Nginx access logs.
- Website data: the public website does not use advertising cookies or analytics. Technical error logs may still be created when a server fault occurs.
3. Purposes and legal grounds
- To provide the requested inference response and administer API access: performance of the service relationship and processing necessary for that service.
- To measure usage and support billing through the provider relationship: performance of the service and Lithune's legitimate interest in accurate accounting.
- To prevent abuse, diagnose failures and protect infrastructure: Lithune's legitimate interest in operating a secure and reliable service.
- To retain records required by applicable law: compliance with legal obligations.
Where Turkish Law No. 6698 applies, processing is carried out under the applicable conditions in Articles 5 and 6. Where the GDPR applies, the corresponding bases may include contract, legitimate interests and legal obligation.
4. Retention
- Prompt and completion content: not written to persistent storage by Lithune; discarded after response delivery.
- Individual request records: limited to the most recent 200 metadata records across the service and no more than 30 days old, whichever limit is reached first.
- Aggregate per-key usage totals: currently retained until the corresponding API-key record is manually deleted. Lithune uses these totals for usage accounting and capacity planning.
- Nginx error logs: only actual errors are recorded; logs are rotated daily with up to 14 rotations normally retained.
5. Recipients and data location
Model inference is performed on Lithune-owned hardware in Türkiye. Lithune does not send inference content to an external model or GPU provider.
Requests may be routed through OpenRouter and Cloudflare. Those organisations may process request, connection or account data for routing, security and platform operation under their own privacy terms, potentially outside Türkiye. Users should review those terms before using the service.
6. Sensitive data
Users should not submit health information, biometric data, political opinions or other sensitive personal data unless they have a lawful basis and the submission is necessary. If included in a prompt, such content is processed transiently to produce the requested response and is not intentionally retained by Lithune.
7. Your rights
Subject to the law applicable to you, you may request information about processing, access, correction, deletion, restriction or objection, and may have rights concerning portability. You may also complain to Türkiye's Personal Data Protection Authority or, where applicable, your local data-protection authority.
Requests can currently be submitted through the official Lithune OpenRouter profile. Lithune may ask for information needed to verify the requester and locate the relevant API-key metadata.
8. Security and changes
Traffic is protected in transit using TLS, and access to infrastructure and retained metadata is restricted. No security measure can provide an absolute guarantee. Material changes to this notice will be reflected by updating the date above.